The log complains about authentication type mismatch and encryption type mismatch, so I’d guess the /ip ipsec row proposal to which the policy template refers does not support any of the authentication and encryption algorithms suggested by the Windows client, but it may be a false alarm.
Open a terminal window in Winbox and follow the hint in my automatic signature right below (by adding file=somefilename to /export hide-sensitive, you’ll be able to download the export rather than copy-pasting it from the terminal window).